ml-logger@0.10.22 vulnerabilities

  • latest version

    0.10.36

  • first published

    7 years ago

  • latest version published

    5 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the ml-logger package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Directory Traversal

    Affected versions of this package are vulnerable to Directory Traversal via the stream_handler function in the file handler component when manipulating the key argument. An unauthenticated user can access sensitive information by sending specially crafted requests remotely.

    How to fix Directory Traversal?

    There is no fixed version for ml-logger.

    [0,)
    • M
    Directory Traversal

    Affected versions of this package are vulnerable to Directory Traversal via the log_handler function. An unauthenticated user can access or modify files outside the intended directory by supplying crafted input to the file argument.

    How to fix Directory Traversal?

    There is no fixed version for ml-logger.

    [0,)
    • M
    Deserialization of Untrusted Data

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the log_handler function of the Ping Handler component in the server process. An attacker can execute arbitrary code or manipulate application behavior by sending specially crafted data to be deserialized remotely.

    How to fix Deserialization of Untrusted Data?

    There is no fixed version for ml-logger.

    [0,)